<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Processing Event Logs in PowerShell</title><link>http://blogs.msdn.com/powershell/archive/2009/05/21/processing-event-logs-in-powershell.aspx</link><description>PowerShell V2 ships with two sets of cmdlets for processing event logs, one is *-EventLog set and other is Get-WinEvent. PS &amp;gt; gcm *EventLog -CommandType cmdlet CommandType Name Definition ----------- ---- ---------- Cmdlet Clear-EventLog Clear-EventLog</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Processing Event Logs in PowerShell</title><link>http://blogs.msdn.com/powershell/archive/2009/05/21/processing-event-logs-in-powershell.aspx#9633671</link><pubDate>Thu, 21 May 2009 15:05:37 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9633671</guid><dc:creator>Russ Pitcher</dc:creator><description>&lt;p&gt;? Limit-EventLog ?&lt;/p&gt;
&lt;p&gt;Surely 'Set' would be a far better choice of verb than 'Limit'?&lt;/p&gt;</description></item><item><title>re: Processing Event Logs in PowerShell</title><link>http://blogs.msdn.com/powershell/archive/2009/05/21/processing-event-logs-in-powershell.aspx#9633793</link><pubDate>Thu, 21 May 2009 17:17:10 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9633793</guid><dc:creator>ichoudhury</dc:creator><description>&lt;p&gt;Why would you even bother to create a new cmdlet rather than enhancing get-eventlog ? &amp;nbsp;I really do appreciate the improvement and I can see why Get-WinEvent would be my choice, but I would have liked it even better if you said .. &amp;quot;Well, Get-eventlog on v2 can do whole lot more than what you are used to&amp;quot; ...&lt;/p&gt;
&lt;p&gt;Hypothetically&lt;/p&gt;
&lt;p&gt;PS &amp;gt; (Get-EventLog -List ).Count&lt;/p&gt;
&lt;p&gt;160 &lt;/p&gt;
&lt;p&gt;:)) &amp;nbsp;&lt;/p&gt;
&lt;p&gt;(I sound annoyed, but actually I am more curious instead)&lt;/p&gt;</description></item><item><title>re: Processing Event Logs in PowerShell</title><link>http://blogs.msdn.com/powershell/archive/2009/05/21/processing-event-logs-in-powershell.aspx#9634533</link><pubDate>Fri, 22 May 2009 03:30:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9634533</guid><dc:creator>Link Hogjowl</dc:creator><description>&lt;p&gt;Link should be &lt;a rel="nofollow" target="_new" href="http://www.computerperformance.co.uk/powershell/powershell_eventlog.htm"&gt;http://www.computerperformance.co.uk/powershell/powershell_eventlog.htm&lt;/a&gt;&lt;/p&gt;</description></item><item><title>re: Processing Event Logs in PowerShell</title><link>http://blogs.msdn.com/powershell/archive/2009/05/21/processing-event-logs-in-powershell.aspx#9636045</link><pubDate>Sat, 23 May 2009 00:46:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9636045</guid><dc:creator>PowerShellTeam</dc:creator><description>&lt;p&gt;RT @Hogjowl : Link has been corrected. Thanks for pointing it out.&lt;/p&gt;
&lt;p&gt;RT @ichoudhury : You are right, it would have been a better experience if Get-EventLog did everything. However, we did this a new cmdlet because a) Windows Vista Event model is very different b) It depends on .NET 3.5 and we didn't want to add to this dependency on Get-Eventlog (which is targeted towards XP/win2k3)&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;Osama&lt;/p&gt;
</description></item><item><title>re: Processing Event Logs in PowerShell</title><link>http://blogs.msdn.com/powershell/archive/2009/05/21/processing-event-logs-in-powershell.aspx#9643837</link><pubDate>Wed, 27 May 2009 10:20:27 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9643837</guid><dc:creator>egb</dc:creator><description>&lt;p&gt;Why do these cmdlets not work for V2 on VISTA?&lt;/p&gt;
&lt;p&gt;I must be missing something, but&lt;/p&gt;
&lt;p&gt;get_WinEvent&lt;/p&gt;
&lt;p&gt;doesn't exist at all and&lt;/p&gt;
&lt;p&gt;gcm *eventlog* -commandtype cmdlet&lt;/p&gt;
&lt;p&gt;produces a single line describing Get_EventLog.&lt;/p&gt;</description></item><item><title>Windows Event Log in PowerShell - Part II</title><link>http://blogs.msdn.com/powershell/archive/2009/05/21/processing-event-logs-in-powershell.aspx#9726159</link><pubDate>Thu, 11 Jun 2009 11:07:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9726159</guid><dc:creator>Windows PowerShell Blog</dc:creator><description>&lt;p&gt;In part 1 of “ Event logs in Powershell ” we talked about differences between Get-EventLog and Get-WinEvent.&lt;/p&gt;
</description></item><item><title>where's backup-eventlog?</title><link>http://blogs.msdn.com/powershell/archive/2009/05/21/processing-event-logs-in-powershell.aspx#9843439</link><pubDate>Tue, 21 Jul 2009 17:56:38 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9843439</guid><dc:creator>marc carter</dc:creator><description>&lt;p&gt;The problem I'm running into is when trying to create a backup (.evt) of the event log on a x64 server. &amp;nbsp;I'm unable to resolve the path for a log file unless I use the WMI class Win32_NTEventLogFile. &amp;nbsp;Which isn't a terrible thing, unfortunetly Win32_NTEventLogFile doesn't seem to know about the system logs on my x64 servers (example results below) which reside in WoW64 (not system32) folder. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;[Win32_NTEventLogFile]&lt;/p&gt;
&lt;p&gt;LogfileName&lt;/p&gt;
&lt;p&gt;-----------&lt;/p&gt;
&lt;p&gt;Internet Explorer&lt;/p&gt;
&lt;p&gt;[Get-EventLog]&lt;/p&gt;
&lt;p&gt;Name &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/p&gt;
&lt;p&gt;---- &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/p&gt;
&lt;p&gt;Application &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Internet Explorer&lt;/p&gt;
&lt;p&gt;Security &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/p&gt;
&lt;p&gt;System &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/p&gt;
&lt;p&gt;Is there a similar .Net property to LogfileName that I can use when calling BackupEventLog in order to grab the file path of each event log?&lt;/p&gt;
&lt;p&gt;The only properties returned by get-eventlog (that I am aware of) are...&lt;/p&gt;
&lt;p&gt;[Properties]&lt;/p&gt;
&lt;p&gt;Container &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/p&gt;
&lt;p&gt;EnableRaisingEvents &lt;/p&gt;
&lt;p&gt;Entries &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/p&gt;
&lt;p&gt;Log &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/p&gt;
&lt;p&gt;LogDisplayName &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/p&gt;
&lt;p&gt;MachineName &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/p&gt;
&lt;p&gt;MaximumKilobytes &amp;nbsp; &amp;nbsp;&lt;/p&gt;
&lt;p&gt;MinimumRetentionDays&lt;/p&gt;
&lt;p&gt;OverflowAction &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Site &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Source &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/p&gt;
&lt;p&gt;SynchronizingObject &lt;/p&gt;</description></item></channel></rss>